Summary:
doc/htaccess.txt recommended security
Detailed Description:
in doc/htaccess.txt
----------------------------
# The following are highly recommended security settings for files in your CMSMS
install that should not be browsed directly.
#
RedirectMatch 403 ^/.*\.htaccess$
RedirectMatch 403 ^/.*\.log$
RedirectMatch 403 ^/.*\.ini$
RedirectMatch 403 ^/.*config\.php$
RedirectMatch 403 ^.*/doc/.*$
RedirectMatch 403 ^.*/lib/.*\.php$
RedirectMatch 403 ^.*/tmp/.*\.php$
RedirectMatch 403 ^.*/modules/.*\.php$
RedirectMatch 403 ^.*/uploads/.*\.php$
RedirectMatch 403 ^.*/assets/.*\.php$
RedirectMatch 403 ^.*/assets/.*\.tpl$
--------------------------------
can slow down server if an attacker sends several extremely long URLs
option 1 : avoid or reduce .* (catastrophic backtracking)
--------------------------------
RedirectMatch 403 \.htaccess$
RedirectMatch 403 (?i)\.log$
RedirectMatch 403 (?i)\.ini$
RedirectMatch 403 (?i)config\.php$
RedirectMatch 403 /doc/
RedirectMatch 403 (?i)/lib/.*\.php$
RedirectMatch 403 (?i)/tmp/.*\.php$
RedirectMatch 403 (?i)/modules/.*\.php$
RedirectMatch 403 (?i)/uploads/.*\.php$
RedirectMatch 403 (?i)/assets/.*\.php$
RedirectMatch 403 (?i)/assets/.*\.tpl$
---shorter version and faster-----------------------------
<FilesMatch "(?i)(?:config\.php|\.(?:htaccess|log|ini))$">
Redirect 403 /
</FilesMatch>
RedirectMatch 403 /doc/
RedirectMatch 403 (?i)/(?:lib|tmp|modules|uploads)/.*\.php$
RedirectMatch 403 (?i)/assets/.*\.tpl$
-------------------------------
option 2 : improve performances (only one backtracking)
root file /.htaccess
-------------------------------
<FilesMatch "(?i)(?:config\.php|\.(?:htaccess|log|ini))$">
Redirect 403 /
</FilesMatch>
RedirectMatch 403 (?i)/tmp/.*\.php$
--------------------------------
folder doc/ CHMOD 700 or 750
/doc/.htaccess
----------------------------------------
<IfModule mod_authz_core.c>
# Apache >= 2.4
Require all denied
</IfModule>
<IfModule !mod_authz_core.c>
# Apache <= 2.2
Order Allow,Deny
</IfModule>
-----------------------------
.htaccess in folders /lib/ , /modules/ and /uploads/
NOTE : not in /tmp/ due to clear cache process from admin
/lib/.htaccess
/modules/.htaccess
/uploads/.htaccess
----------------------------------------
<FilesMatch "(?i)\.php$">
Redirect 403 /
</FilesMatch>
-----------------------------
.htaccess in folders /assets/
assets/.htaccess
----------------------------------------
<FilesMatch "(?i)\.(?:php|tpl)$">
Redirect 403 /
</FilesMatch>
-----------------------------
Note : security through obscurity return 404 instead 403
replace everywhere all 403 by 404
and
in /doc/.htaccess
replace all code by
Redirect 404 /